Scanning for SQL Injection



Hi. I need to scan about 350+ sites from three different web servers that all connect to one MS SQL server for SQL injection. Any ideas on how to make this not take a long long time?

I like the Priamos tool but you can only scan one site at a time, and you can't load a list of any sort, etc.

Any input is appreciated

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Swap Out your SPI or Watchfire app sec solution for
Cenzic's robust, accurate risk assessment and management
solution FREE - limited Time Offer

http://www.cenzic.com/wf-spi
------------------------------------------------------------------------



Relevant Pages

  • Re: Scanning for SQL Injection
    ... Subject: Scanning for SQL Injection ... I need to scan about 350+ sites from three different web servers that ... Paros will need a starting seed URL list. ... solution FREE - limited Time Offer ...
    (Pen-Test)
  • Re: ms sql server grabbing 5Gb. Is this good nomal?
    ... some Web Servers running IIS 6, being served by another box running MS ... SQL Server 2005. ... issuing inherently inefficient queries or both. ...
    (microsoft.public.dotnet.languages.csharp)
  • SSL Security Error
    ... We have two web servers load balanced by ... We are using ASP.NET 1.1 and authenticating to SQL server 2005 using ... integrated authentication. ... System.Data.SqlClient.SqlConnectionPoolManager.GetPooledConnection(SqlConnectionString options, Boolean& isInTransaction) ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: ms sql server grabbing 5Gb. Is this good nomal?
    ... The queries to find missing indexes and to find unusedindexes is ... You can also look at the Sql Server Dashboard Reports, ... some Web Servers running IIS 6, being served by another box running MS ...
    (microsoft.public.dotnet.languages.csharp)
  • Re: Load Balancing
    ... SQL Server is not Load Balance aware. ... Even with clustering does not ... You could have load balance your web servers, ...
    (microsoft.public.sqlserver.replication)

Quantcast